Live data from Hacker News

Encrypted email is still a pain

incoherency.co.uk

301–310 of 450 posts

Re: Encrypted email is still a pain

#302
post #89

Earlier quoted context omitted.

> In modern messaging protocols, they don't have to care about encryption. The protocols are designed to reliably encrypt messages without user intervention, and security isn't "opt-in". Sounds good. Doesn't sound worth giving up decentralisation for. Doesn't even seem like something we'd need to give up OpenPGP to get - if client design were equal (and it isn't at the moment, but I see no reason it can't be) I'd far…

What's the benefit of decentralization? Not being snarky, I just don't really see it. What does a decentralized PGP email have that I don't have with my Signal Messenger? Also, given how PGP works I fail to see how you can claim that you can achieve comparable client design/ease of use/UX to Signal. At the very least it appears evident to me that the problem is much much harder than Signal (and it should be, Signal w…

Decentralization is good to help protect the user against abuses from the central service provider.

It also encourages competition, since the user can switch to a different service, and not be penalized by network effects preventing them from communicating with other people.

I use MX records in my domain so that I can switch to any mail provider I want, and people will still be able to contact me with the same address.

How is this possible in a centralized system? If I switch from WhatsApp to Signal, I lose all my contacts. If I want to keep communicating with them, then I have to convince them to switch to a different app, or just never stop using whatsapp. The network effects dynamic here makes it very difficult to switch from one centralized encrypted chat provider to another. If you try to leave, you lose all your contacts.

The other thing I dislike is that they all seem to require a valid phone number. This puts you at the mercy of the phone company. If you change your phone number, then you have to get all your contacts to change their contact info for you. This is a huge step back, compared to email with own domain and MX records!

The other thing I dislike about these centralized encrypted chat providers is the lack of client choice. 1 company can only support so many platforms, fair enough. But that will likely mean I'll never see the company develop a Linux desktop client, or a terminal based client for their network. And because of centralization, no-one else will be allowed to develop one either. In contrast, there are many different tools I can use for sending and receiving email on the Linux desktop, cli based backup tools, etc.

And as far as the spam problem goes, I'm not sure how Signal/WhatsApp are better in this regard? If you have to give your signal address to out for people to communicate with you, or to do business with a company, then I don't see why companies can't just spam you. Signal can centrally filter all messages you receive to make sure they don't have spam in them and block spammers messages from going through (but this is no different than what many mail providers also do). You can block individual contacts, but that doesn't help if there are a very large number of different accounts sending spam. You can whitelist your contacts, but then noone you don't know that wants to talk to you can contact you.

It also doesn't stop known contacts from sending spam to you either because

- They are forwarding spam messages to you, like chain letters.

- They got a virus or some malware which sends spam to all their contacts

- It's a "legit" company you need to receive communication with, but sends spam mixed with vital communication: marketing lists you get auto-opted into (imagine if all the "give us your email to read the article" pop overs got replaced with "add us on signal to read the article"), amazon sale ads, facebook constantly trying to entice you to go back on the site, etc.

If signal replaced email, I don't see how it could remain spam free.

Re: Encrypted email is still a pain

#304
post #293

Earlier quoted context omitted.

> The problem with the web of trust is that it simply doesn't work: the fact that I know you means nothing about whether I trust you to vouch for others. Actually it means a lot. That's how trust works in the real world as well.

You don't know any deadbeats you trust less than a random person selected from the population at large?

The "web of trust" is not about trusting everybody you happen to merely know.

It's, and the name is kind of a hint, about knowing those you trust -- it's a web in that there's higher level trust (people you personally know and trust yourself), secondary trust (people trusted by those you trust), etc.

And in cryptography it's even more specific: https://en.wikipedia.org/wiki/Web_of_trust

It's not in any way about trusting someone just because you know them.

Re: Encrypted email is still a pain

#305
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

It is an absolute violation of my expectations for you to say that a browser cannot meaningfully implement crypto.

Re: Encrypted email is still a pain

#306
post #44
post #4

Ooh, I know this one! I think. Doesn't Apple Mail have this built in? I go to Keychain Access, choose the option to generate a key. Two clicks. Head to Mail, encryption options are there. Now, to import his key. Do some googling on that. Wait, what? Apple Mail supports S/MIME, not GPG. Competing standards strike again. If the other person has S/MIME, Apple Mail does have a very easy experience. I can't speak for the…

I'm glad S/MIME gets a mention because I've always been skeptical of it based on the fact that everyone rallies behind PGP. I recently failed to install gpg2 on freebsd (for some reason it barks at me and fails and I don't care enough to waste my time on it) and decided to give S/MIME a chance with a signed cert from comodo. (which was free, just to try) I have to say though the experience is beyond reasonable, it's…

Well, this just convinced me to snag a cert for myself. Are there any services like keybase for sharing S/MIME public keys?

Re: Encrypted email is still a pain

#307
post #91

Earlier quoted context omitted.

By making the discredited argument that WhatsApp's key-change behavior is a fatal flaw, you're disagreeing with: * The EFF * Moxie Marlinspike * Matthew Green * Bruce Schneier * Isis Lovecruft from Tor * the grugq * Matt Blaze * Avi Rubin * Steve Bellovin * Joseph Lorenzo Hall * Bart Preneel * Peter Honeyman * Jon Callas (who cofounded PGP Corp) * Paulo Barreto ... and about 50 more experts equally respected in the f…

"you're disagreeing with" This is the problem with the security community, always with authoritative arguments. Building a religion around security is not going to end well. Some of those people already push government agendas and people eat it, because they were told not to question "experts".

It's not just security. Nicholas Nassim Taleb even invented a word for this kind of thing. He describes his complaint, in typical pugnacious Taleb style, here: https://medium.com/incerto/the-intellectual-yet-idiot-13211e...

Re: Encrypted email is still a pain

#308

Keybase, Nylas mail plugin. Done. or GPG Tools beta, Mail app, done. or even just the Keybase built in encrypt/decrypt.

I wanted to give this a go, I downloaded nylas but there aint no Encryption plugin or anything. How do you go about configuring it ?

For now, the encryption plugin is only available on the older version, Nylas Pro. No reason for that other than time to port and QA the plugin to the new free version, which has a completely written mail sync engine that runs locally rather than in the cloud. We're working on porting all Nylas Pro features to the new version as fast as we can!

If you want to keep up to date about the latest features, you can sign up for our newsletter at the bottom of this page: https://nylas.com/nylas-mail/

Re: Encrypted email is still a pain

#309
post #234
post #170

Earlier quoted context omitted.

> The emerging consensus among experts "conseunsus"? a few blog posts about some bad user experience with GnuPG / the PGP ecosystem is, at best, just an (re)emerging topic on HN, not the end of email encryption. OpenPGP implementations may not be the easiest encryption software out there (its usability issues have been discussed for two decades now) but that's simply because PGP was not designed to be used by the lai…

Why use PGP anymore when you can use Keybase and the next generation of key management? Instead of having one master key for your identity, the paradigm is changed: Identity is a set of claims "X on domain A is Y on domain B". That's it. "Domain" can refer to a server-based service such as reddit, or a client app on a device. Such proofs are easy: 1) For public identity on sites which don't support this scheme, X sim…

There is an RFC extension for OpenPGP that does just that: https://tools.ietf.org/html/draft-vb-openpgp-linked-ids-00

It's implemented in Android OpenKeychain.

Re: Encrypted email is still a pain

#310
post #305
post #7

Encrypted email is pretty much over in 2017. The emerging consensus among experts is that it's not worth the trouble, or, worse, incapable of doing much more than generating a false sense of security. That's for a bunch of reasons: * An enormous installed base of clients that won't do encryption, meaning that at best you're attempting to tunnel encrypted messaging over an unencrypted transport. * A protocol that leak…

It is an absolute violation of my expectations for you to say that a browser cannot meaningfully implement crypto.

[deleted]
Post reply on HN